{
 "all_hold": true,
 "authority": "NONE",
 "checked": 305,
 "checks": [
  {
   "detail": {
    "dispatch": "VERIFIED",
    "teleport": "CLAIMED"
   },
   "holds": true,
   "id": "NET-I001",
   "invariant": "discovery cannot create authority"
  },
  {
   "detail": [
    "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
   ],
   "holds": true,
   "id": "NET-I002",
   "invariant": "communication cannot create authority"
  },
  {
   "detail": [
    "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
   ],
   "holds": true,
   "id": "NET-I003",
   "invariant": "negotiation cannot create authority"
  },
  {
   "detail": [
    "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
   ],
   "holds": true,
   "id": "NET-I004",
   "invariant": "contract cannot create authority"
  },
  {
   "detail": [
    "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
   ],
   "holds": true,
   "id": "NET-I005",
   "invariant": "reputation cannot create authority"
  },
  {
   "detail": [
    "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
   ],
   "holds": true,
   "id": "NET-I006",
   "invariant": "payment cannot create authority"
  },
  {
   "detail": [
    "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
   ],
   "holds": true,
   "id": "NET-I007",
   "invariant": "coalition cannot create authority"
  },
  {
   "detail": [
    "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
   ],
   "holds": true,
   "id": "NET-I008",
   "invariant": "federation cannot create authority"
  },
  {
   "detail": {
    "authority": "NONE",
    "effective": [
     "read"
    ],
    "ignored_inputs": [
     "trust_score"
    ],
    "state": "COMPILED",
    "unknown_factors": []
   },
   "holds": true,
   "id": "NET-I009",
   "invariant": "trust cannot create unlimited authority"
  },
  {
   "detail": {
    "dispatch": "VERIFIED",
    "teleport": "CLAIMED"
   },
   "holds": true,
   "id": "NET-I010",
   "invariant": "capability advertisement cannot create authority"
  },
  {
   "detail": [],
   "holds": true,
   "id": "NET-I011",
   "invariant": "child authority \u2286 delegated authority"
  },
  {
   "detail": [
    "FEDERATION_SCOPE_EXCEEDS_DOMAIN_POLICY"
   ],
   "holds": true,
   "id": "NET-I012",
   "invariant": "cross-domain authority \u2286 local \u2229 remote policy"
  },
  {
   "detail": [
    0.0,
    0.1,
    0.2,
    0.3,
    0.4,
    0.5,
    0.6,
    0.7,
    0.8,
    0.9,
    1.0
   ],
   "holds": true,
   "id": "NET-I013",
   "invariant": "trust translation cannot silently increase authority"
  },
  {
   "detail": [
    "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY",
    "PROTOCOL_OPERATION_UNMAPPED"
   ],
   "holds": true,
   "id": "NET-I014",
   "invariant": "protocol translation cannot silently increase authority"
  },
  {
   "detail": [
    "CALLER_IDENTITY_SIGNATURE_INVALID",
    "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
   ],
   "holds": true,
   "id": "NET-I015",
   "invariant": "identity translation cannot silently increase authority"
  },
  {
   "detail": [
    "AGENT_STATE_REVOKED:agent-a",
    "CALLER_IDENTITY_REVOKED",
    "CONTRACT_PARTY_REVOKED",
    "CONTRACT_REVOKED",
    "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY",
    "TRUST:TRUST_INSUFFICIENT:behavioral_trust",
    "TRUST:TRUST_INSUFFICIENT:security_trust"
   ],
   "holds": true,
   "id": "NET-I016",
   "invariant": "revoked identity cannot transact"
  },
  {
   "detail": [
    "CAPABILITY_REVOKED",
    "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
   ],
   "holds": true,
   "id": "NET-I017",
   "invariant": "revoked capability cannot execute"
  },
  {
   "detail": [
    "CAPABILITY_STALE",
    "CONTRACT_EXPIRED_OR_NOT_YET_VALID",
    "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY",
    "TRUST:TRUST_UNKNOWN:behavioral_trust",
    "TRUST:TRUST_UNKNOWN:identity_trust",
    "TRUST:TRUST_UNKNOWN:security_trust"
   ],
   "holds": true,
   "id": "NET-I018",
   "invariant": "expired contract cannot authorize"
  },
  {
   "detail": "STALE",
   "holds": true,
   "id": "NET-I019",
   "invariant": "expired evidence cannot authorize"
  },
  {
   "detail": [
    "REATTESTATION_REQUIRED"
   ],
   "holds": true,
   "id": "NET-I020",
   "invariant": "quarantined agent cannot regain authority without reattestation"
  },
  {
   "detail": {
    "A_AND_C_CONTINUE_WHERE_SAFE": true,
    "NETWORK_DID_NOT_COLLAPSE": true
   },
   "holds": true,
   "id": "NET-I021",
   "invariant": "agent compromise cannot automatically compromise every peer"
  },
  {
   "detail": [
    [],
    []
   ],
   "holds": true,
   "id": "NET-I022",
   "invariant": "incident propagation must preserve unrelated trust domains"
  },
  {
   "detail": 43,
   "holds": true,
   "id": "NET-I023",
   "invariant": "quarantine cannot erase evidence"
  },
  {
   "detail": [
    "QUARANTINED",
    "RECOVERING",
    "RESTORED"
   ],
   "holds": true,
   "id": "NET-I024",
   "invariant": "recovery cannot erase incident history"
  },
  {
   "detail": [
    "REVOKED_IDENTITY_CANNOT_BE_REISSUED"
   ],
   "holds": true,
   "id": "NET-I025",
   "invariant": "rollback cannot resurrect revoked authority"
  },
  {
   "detail": [
    "CAPABILITY_CLAIMED",
    "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
   ],
   "holds": true,
   "id": "NET-I026",
   "invariant": "economic resources cannot mint authority"
  },
  {
   "detail": 0.5,
   "holds": true,
   "id": "NET-I027",
   "invariant": "reputation cannot mint authority"
  },
  {
   "detail": "GOVERNANCE_INPUT",
   "holds": true,
   "id": "NET-I028",
   "invariant": "arbitration cannot mint unlimited authority"
  },
  {
   "detail": [
    "NEGOTIATION_CANNOT_TRADE_AUTHORITY",
    "NEGOTIATION_NOT_AGREED",
    "NEGOTIATION_TERM_UNKNOWN:authority"
   ],
   "holds": true,
   "id": "NET-I029",
   "invariant": "negotiation cannot bypass policy"
  },
  {
   "detail": "6f3702d0936d6ecc9343a92a877a026ca8cb8f3fc367b377a5e5c6572d0efc6e",
   "holds": true,
   "id": "NET-I030",
   "invariant": "contract fulfillment cannot bypass E8"
  },
  {
   "detail": [
    "AUTHORIZED",
    []
   ],
   "holds": true,
   "id": "NET-I031",
   "invariant": "MCP execution reaches E8"
  },
  {
   "detail": [
    "AUTHORIZED",
    []
   ],
   "holds": true,
   "id": "NET-I032",
   "invariant": "A2A consequential delegation reaches E8"
  },
  {
   "detail": [
    "DENY",
    [
     "CAPABILITY_CLAIMED",
     "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
    ]
   ],
   "holds": true,
   "id": "NET-I033",
   "invariant": "computer-use actions reach E8"
  },
  {
   "detail": [
    "AUTHORIZED",
    []
   ],
   "holds": true,
   "id": "NET-I034",
   "invariant": "API actions reach E8"
  },
  {
   "detail": [
    "AUTHORIZED",
    []
   ],
   "holds": true,
   "id": "NET-I035",
   "invariant": "physical consequential actions reach E8"
  },
  {
   "detail": [
    "DEPENDENCY_UNAVAILABLE:network-partition:dom-b"
   ],
   "holds": true,
   "id": "NET-I036",
   "invariant": "network partition cannot expand authority"
  },
  {
   "detail": [
    "DEPENDENCY_UNAVAILABLE:revocation-provider"
   ],
   "holds": true,
   "id": "NET-I037",
   "invariant": "revocation outage cannot expand authority"
  },
  {
   "detail": [
    "CALLER_IDENTITY_PROVIDER_UNAVAILABLE",
    "DEPENDENCY_UNAVAILABLE:identity-provider",
    "TARGET_IDENTITY_PROVIDER_UNAVAILABLE"
   ],
   "holds": true,
   "id": "NET-I038",
   "invariant": "identity outage cannot expand authority"
  },
  {
   "detail": [
    "DEPENDENCY_UNAVAILABLE:evidence-provider"
   ],
   "holds": true,
   "id": "NET-I039",
   "invariant": "evidence outage cannot expand authority"
  },
  {
   "detail": [
    "PROTOCOL_DOWNGRADE"
   ],
   "holds": true,
   "id": "NET-I040",
   "invariant": "protocol downgrade cannot expand authority"
  },
  {
   "detail": [
    "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY",
    "TRUST:TRUST_UNKNOWN:identity_trust"
   ],
   "holds": true,
   "id": "NET-I041",
   "invariant": "unknown trust remains unknown"
  },
  {
   "detail": [
    "AGENT_STATE_UNKNOWN:agent-ghost",
    "CALLER_IDENTITY_UNKNOWN",
    "CROSS_DOMAIN_AUTHORITY_UNKNOWN"
   ],
   "holds": true,
   "id": "NET-I042",
   "invariant": "unknown identity remains unknown"
  },
  {
   "detail": [
    "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY",
    "PROTOCOL_OPERATION_UNMAPPED"
   ],
   "holds": true,
   "id": "NET-I043",
   "invariant": "unknown capability remains unknown"
  },
  {
   "detail": [
    "PUBLISHER_UNKNOWN"
   ],
   "holds": true,
   "id": "NET-I044",
   "invariant": "unknown provenance remains unknown"
  },
  {
   "detail": [
    "context"
   ],
   "holds": true,
   "id": "NET-I045",
   "invariant": "unknown execution state remains unknown"
  },
  {
   "detail": [],
   "holds": true,
   "id": "NET-I046",
   "invariant": "the legitimate cross-domain chain commits through E19 and E8"
  },
  {
   "detail": [],
   "holds": true,
   "id": "NET-I047",
   "invariant": "every discovery answers the eight questions"
  },
  {
   "detail": [
    "DISCOVERY_ADVERTISEMENT_NOT_PROVENANCE_BOUND"
   ],
   "holds": true,
   "id": "NET-I048",
   "invariant": "a forged discovery advertisement is refused"
  },
  {
   "detail": {
    "authority": "NONE",
    "collapsed_to_single_score": false,
    "dims": {
     "behavioral_trust": 0.1,
     "capability_trust": null,
     "communication_trust": null,
     "cross_domain_trust": null,
     "delegation_trust": null,
     "economic_trust": null,
     "evidence_trust": null,
     "execution_trust": null,
     "identity_trust": 0.9,
     "organizational_trust": null,
     "policy_trust": null,
     "provenance_trust": null,
     "security_trust": null,
     "temporal_trust": null
    }
   },
   "holds": true,
   "id": "NET-I049",
   "invariant": "trust is a 14-dimension vector, never one score"
  },
  {
   "detail": [
    "TRUST_INSUFFICIENT:behavioral_trust",
    "TRUST_UNKNOWN:security_trust"
   ],
   "holds": true,
   "id": "NET-I050",
   "invariant": "mixed trust states coexist (high identity, low behaviour, unknown security)"
  },
  {
   "detail": [
    "dispatch"
   ],
   "holds": true,
   "id": "NET-I051",
   "invariant": "hiring grants exactly the minimum authority"
  },
  {
   "detail": [],
   "holds": true,
   "id": "NET-I052",
   "invariant": "a legitimate escrow settles and is labelled SIMULATED"
  },
  {
   "detail": [
    500.0,
    500.0
   ],
   "holds": true,
   "id": "NET-I053",
   "invariant": "escrow conserves abstract units"
  },
  {
   "detail": [
    "QUARANTINED",
    "RECOVERING",
    "RESTORED"
   ],
   "holds": true,
   "id": "NET-I054",
   "invariant": "a legitimately re-attested agent is restored with its history intact"
  },
  {
   "detail": [],
   "holds": true,
   "id": "NET-I055",
   "invariant": "a legitimate two-hop delegation chain narrows"
  },
  {
   "detail": [
    0.0,
    0.1,
    0.2,
    0.3,
    0.4,
    0.5,
    0.6,
    0.7,
    0.8,
    0.9,
    1.0
   ],
   "holds": true,
   "id": "NET-I056",
   "invariant": "numeric trust translation is monotone and bounded"
  },
  {
   "detail": "VERIFIED is not HIGH",
   "holds": true,
   "id": "NET-I057",
   "invariant": "VERIFIED is not translated as HIGH"
  },
  {
   "detail": [
    "agent",
    "authority",
    "authority_bom",
    "capability_bom",
    "dependency_bom",
    "digest",
    "identity",
    "model_bom",
    "protocol_bom",
    "trust_bom"
   ],
   "holds": true,
   "id": "NET-I058",
   "invariant": "the MachineSystemBOM has all sections and no authority"
  },
  {
   "detail": [],
   "holds": true,
   "id": "NET-I059",
   "invariant": "legitimate shared memory carries provenance and no authority"
  },
  {
   "detail": "admitted",
   "holds": true,
   "id": "NET-I060",
   "invariant": "a legitimate signed artifact is admitted"
  },
  {
   "detail": [
    "AUTHORIZED",
    "DENY"
   ],
   "holds": true,
   "id": "NET-I061",
   "invariant": "the governance clock: authorized now, not authorized later"
  },
  {
   "detail": [],
   "holds": true,
   "id": "NET-I062",
   "invariant": "no non-authority input is read by the authority functions"
  },
  {
   "detail": "tamper detected",
   "holds": true,
   "id": "NET-I063",
   "invariant": "the evidence log is hash-chained and tamper-evident"
  },
  {
   "detail": 20,
   "holds": true,
   "id": "NET-I064",
   "invariant": "the network has 20 constitutional laws"
  },
  {
   "detail": {
    "expired": [
     "DELEGATION_SIGNATURE_INVALID",
     "DELEGATION_EXPIRED"
    ],
    "revoked": [
     "DELEGATION_REVOKED"
    ]
   },
   "holds": true,
   "id": "NET-I065",
   "invariant": "a revoked or expired delegation is not live"
  },
  {
   "detail": [
    "AUTHORIZED",
    []
   ],
   "holds": true,
   "id": "NET-P-a2a-tasks/send",
   "invariant": "a2a tasks/send: an authorization always comes from an E8 commit"
  },
  {
   "detail": [
    "AUTHORIZED",
    []
   ],
   "holds": true,
   "id": "NET-P-a2a-tasks/get",
   "invariant": "a2a tasks/get: an authorization always comes from an E8 commit"
  },
  {
   "detail": [
    "AUTHORIZED",
    []
   ],
   "holds": true,
   "id": "NET-P-a2a-message/send",
   "invariant": "a2a message/send: an authorization always comes from an E8 commit"
  },
  {
   "detail": [
    "AUTHORIZED",
    []
   ],
   "holds": true,
   "id": "NET-P-mcp-tools/call:read_record",
   "invariant": "mcp tools/call:read_record: an authorization always comes from an E8 commit"
  },
  {
   "detail": [
    "AUTHORIZED",
    []
   ],
   "holds": true,
   "id": "NET-P-mcp-tools/call:dispatch_order",
   "invariant": "mcp tools/call:dispatch_order: an authorization always comes from an E8 commit"
  },
  {
   "detail": [
    "AUTHORIZED",
    []
   ],
   "holds": true,
   "id": "NET-P-mcp-tools/call:write_record",
   "invariant": "mcp tools/call:write_record: an authorization always comes from an E8 commit"
  },
  {
   "detail": [
    "AUTHORIZED",
    []
   ],
   "holds": true,
   "id": "NET-P-mcp-resources/read",
   "invariant": "mcp resources/read: an authorization always comes from an E8 commit"
  },
  {
   "detail": [
    "AUTHORIZED",
    []
   ],
   "holds": true,
   "id": "NET-P-http-GET",
   "invariant": "http GET: an authorization always comes from an E8 commit"
  },
  {
   "detail": [
    "AUTHORIZED",
    []
   ],
   "holds": true,
   "id": "NET-P-http-POST",
   "invariant": "http POST: an authorization always comes from an E8 commit"
  },
  {
   "detail": [
    "AUTHORIZED",
    []
   ],
   "holds": true,
   "id": "NET-P-http-PUT",
   "invariant": "http PUT: an authorization always comes from an E8 commit"
  },
  {
   "detail": [
    "AUTHORIZED",
    []
   ],
   "holds": true,
   "id": "NET-P-http-DELETE",
   "invariant": "http DELETE: an authorization always comes from an E8 commit"
  },
  {
   "detail": [
    "AUTHORIZED",
    []
   ],
   "holds": true,
   "id": "NET-P-rest-GET",
   "invariant": "rest GET: an authorization always comes from an E8 commit"
  },
  {
   "detail": [
    "AUTHORIZED",
    []
   ],
   "holds": true,
   "id": "NET-P-rest-POST",
   "invariant": "rest POST: an authorization always comes from an E8 commit"
  },
  {
   "detail": [
    "AUTHORIZED",
    []
   ],
   "holds": true,
   "id": "NET-P-grpc-Query",
   "invariant": "grpc Query: an authorization always comes from an E8 commit"
  },
  {
   "detail": [
    "AUTHORIZED",
    []
   ],
   "holds": true,
   "id": "NET-P-grpc-Mutate",
   "invariant": "grpc Mutate: an authorization always comes from an E8 commit"
  },
  {
   "detail": [
    "AUTHORIZED",
    []
   ],
   "holds": true,
   "id": "NET-P-websocket-subscribe",
   "invariant": "websocket subscribe: an authorization always comes from an E8 commit"
  },
  {
   "detail": [
    "AUTHORIZED",
    []
   ],
   "holds": true,
   "id": "NET-P-websocket-publish",
   "invariant": "websocket publish: an authorization always comes from an E8 commit"
  },
  {
   "detail": [
    "AUTHORIZED",
    []
   ],
   "holds": true,
   "id": "NET-P-event_bus-emit",
   "invariant": "event_bus emit: an authorization always comes from an E8 commit"
  },
  {
   "detail": [
    "AUTHORIZED",
    []
   ],
   "holds": true,
   "id": "NET-P-message_queue-enqueue",
   "invariant": "message_queue enqueue: an authorization always comes from an E8 commit"
  },
  {
   "detail": [
    "AUTHORIZED",
    []
   ],
   "holds": true,
   "id": "NET-P-cli-cat",
   "invariant": "cli cat: an authorization always comes from an E8 commit"
  },
  {
   "detail": [
    "DENY",
    [
     "CAPABILITY_CLAIMED",
     "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
    ]
   ],
   "holds": true,
   "id": "NET-P-cli-run",
   "invariant": "cli run: an authorization always comes from an E8 commit"
  },
  {
   "detail": [
    "AUTHORIZED",
    []
   ],
   "holds": true,
   "id": "NET-P-browser-navigate",
   "invariant": "browser navigate: an authorization always comes from an E8 commit"
  },
  {
   "detail": [
    "AUTHORIZED",
    []
   ],
   "holds": true,
   "id": "NET-P-browser-click:submit_payment",
   "invariant": "browser click:submit_payment: an authorization always comes from an E8 commit"
  },
  {
   "detail": [
    "DENY",
    [
     "CAPABILITY_CLAIMED",
     "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
    ]
   ],
   "holds": true,
   "id": "NET-P-browser-click:submit_order",
   "invariant": "browser click:submit_order: an authorization always comes from an E8 commit"
  },
  {
   "detail": [
    "AUTHORIZED",
    []
   ],
   "holds": true,
   "id": "NET-P-browser-type",
   "invariant": "browser type: an authorization always comes from an E8 commit"
  },
  {
   "detail": [
    "AUTHORIZED",
    []
   ],
   "holds": true,
   "id": "NET-P-computer_use-screenshot",
   "invariant": "computer_use screenshot: an authorization always comes from an E8 commit"
  },
  {
   "detail": [
    "DENY",
    [
     "CAPABILITY_CLAIMED",
     "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
    ]
   ],
   "holds": true,
   "id": "NET-P-computer_use-click:submit_order",
   "invariant": "computer_use click:submit_order: an authorization always comes from an E8 commit"
  },
  {
   "detail": [
    "AUTHORIZED",
    []
   ],
   "holds": true,
   "id": "NET-P-computer_use-click:submit_payment",
   "invariant": "computer_use click:submit_payment: an authorization always comes from an E8 commit"
  },
  {
   "detail": [
    "DENY",
    [
     "CAPABILITY_CLAIMED",
     "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
    ]
   ],
   "holds": true,
   "id": "NET-P-computer_use-terminal:run",
   "invariant": "computer_use terminal:run: an authorization always comes from an E8 commit"
  },
  {
   "detail": [
    "AUTHORIZED",
    []
   ],
   "holds": true,
   "id": "NET-P-computer_use-file:write",
   "invariant": "computer_use file:write: an authorization always comes from an E8 commit"
  },
  {
   "detail": [
    "AUTHORIZED",
    []
   ],
   "holds": true,
   "id": "NET-P-local_ipc-call:read",
   "invariant": "local_ipc call:read: an authorization always comes from an E8 commit"
  },
  {
   "detail": [
    "AUTHORIZED",
    []
   ],
   "holds": true,
   "id": "NET-P-local_ipc-call:write",
   "invariant": "local_ipc call:write: an authorization always comes from an E8 commit"
  },
  {
   "detail": [
    "AUTHORIZED",
    []
   ],
   "holds": true,
   "id": "NET-P-cloud_api-Describe",
   "invariant": "cloud_api Describe: an authorization always comes from an E8 commit"
  },
  {
   "detail": [
    "DENY",
    [
     "CAPABILITY_CLAIMED",
     "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
    ]
   ],
   "holds": true,
   "id": "NET-P-cloud_api-Update",
   "invariant": "cloud_api Update: an authorization always comes from an E8 commit"
  },
  {
   "detail": [
    "DENY",
    [
     "CAPABILITY_CLAIMED",
     "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
    ]
   ],
   "holds": true,
   "id": "NET-P-cloud_api-Terminate",
   "invariant": "cloud_api Terminate: an authorization always comes from an E8 commit"
  },
  {
   "detail": null,
   "holds": true,
   "id": "NET-Q-active",
   "invariant": "quarantine state ACTIVE never raises authority"
  },
  {
   "detail": [
    "notify",
    "read"
   ],
   "holds": true,
   "id": "NET-Q-restricted",
   "invariant": "quarantine state RESTRICTED never raises authority"
  },
  {
   "detail": [
    "read"
   ],
   "holds": true,
   "id": "NET-Q-suspected",
   "invariant": "quarantine state SUSPECTED never raises authority"
  },
  {
   "detail": [],
   "holds": true,
   "id": "NET-Q-quarantined",
   "invariant": "quarantine state QUARANTINED never raises authority"
  },
  {
   "detail": [],
   "holds": true,
   "id": "NET-Q-isolated",
   "invariant": "quarantine state ISOLATED never raises authority"
  },
  {
   "detail": [],
   "holds": true,
   "id": "NET-Q-revoked",
   "invariant": "quarantine state REVOKED never raises authority"
  },
  {
   "detail": [
    "read"
   ],
   "holds": true,
   "id": "NET-Q-recovering",
   "invariant": "quarantine state RECOVERING never raises authority"
  },
  {
   "detail": null,
   "holds": true,
   "id": "NET-Q-restored",
   "invariant": "quarantine state RESTORED never raises authority"
  },
  {
   "detail": "terminal",
   "holds": true,
   "id": "NET-Q-revoked-terminal",
   "invariant": "REVOKED has no outgoing transition"
  },
  {
   "detail": [
    "local"
   ],
   "holds": true,
   "id": "NET-F-unknown-local",
   "invariant": "factor 'local' unknown makes authority empty"
  },
  {
   "detail": [
    "read"
   ],
   "holds": true,
   "id": "NET-F-narrows-local",
   "invariant": "factor 'local' narrows authority"
  },
  {
   "detail": [
    "remote"
   ],
   "holds": true,
   "id": "NET-F-unknown-remote",
   "invariant": "factor 'remote' unknown makes authority empty"
  },
  {
   "detail": [
    "read"
   ],
   "holds": true,
   "id": "NET-F-narrows-remote",
   "invariant": "factor 'remote' narrows authority"
  },
  {
   "detail": [
    "delegated"
   ],
   "holds": true,
   "id": "NET-F-unknown-delegated",
   "invariant": "factor 'delegated' unknown makes authority empty"
  },
  {
   "detail": [
    "read"
   ],
   "holds": true,
   "id": "NET-F-narrows-delegated",
   "invariant": "factor 'delegated' narrows authority"
  },
  {
   "detail": [
    "contract_scope"
   ],
   "holds": true,
   "id": "NET-F-unknown-contract_scope",
   "invariant": "factor 'contract_scope' unknown makes authority empty"
  },
  {
   "detail": [
    "read"
   ],
   "holds": true,
   "id": "NET-F-narrows-contract_scope",
   "invariant": "factor 'contract_scope' narrows authority"
  },
  {
   "detail": [
    "policy"
   ],
   "holds": true,
   "id": "NET-F-unknown-policy",
   "invariant": "factor 'policy' unknown makes authority empty"
  },
  {
   "detail": [
    "read"
   ],
   "holds": true,
   "id": "NET-F-narrows-policy",
   "invariant": "factor 'policy' narrows authority"
  },
  {
   "detail": [
    "risk"
   ],
   "holds": true,
   "id": "NET-F-unknown-risk",
   "invariant": "factor 'risk' unknown makes authority empty"
  },
  {
   "detail": [
    "read"
   ],
   "holds": true,
   "id": "NET-F-narrows-risk",
   "invariant": "factor 'risk' narrows authority"
  },
  {
   "detail": [
    "capability"
   ],
   "holds": true,
   "id": "NET-F-unknown-capability",
   "invariant": "factor 'capability' unknown makes authority empty"
  },
  {
   "detail": [
    "read"
   ],
   "holds": true,
   "id": "NET-F-narrows-capability",
   "invariant": "factor 'capability' narrows authority"
  },
  {
   "detail": [
    "resource"
   ],
   "holds": true,
   "id": "NET-F-unknown-resource",
   "invariant": "factor 'resource' unknown makes authority empty"
  },
  {
   "detail": [
    "read"
   ],
   "holds": true,
   "id": "NET-F-narrows-resource",
   "invariant": "factor 'resource' narrows authority"
  },
  {
   "detail": [
    "time"
   ],
   "holds": true,
   "id": "NET-F-unknown-time",
   "invariant": "factor 'time' unknown makes authority empty"
  },
  {
   "detail": [
    "read"
   ],
   "holds": true,
   "id": "NET-F-narrows-time",
   "invariant": "factor 'time' narrows authority"
  },
  {
   "detail": [
    "context"
   ],
   "holds": true,
   "id": "NET-F-unknown-context",
   "invariant": "factor 'context' unknown makes authority empty"
  },
  {
   "detail": [
    "read"
   ],
   "holds": true,
   "id": "NET-F-narrows-context",
   "invariant": "factor 'context' narrows authority"
  },
  {
   "detail": "VERIFIED",
   "holds": true,
   "id": "NET-C-agent-a-delegate",
   "invariant": "agent-a/delegate is VERIFIED only while its evidence is fresh"
  },
  {
   "detail": "VERIFIED",
   "holds": true,
   "id": "NET-C-agent-a-dispatch",
   "invariant": "agent-a/dispatch is VERIFIED only while its evidence is fresh"
  },
  {
   "detail": "VERIFIED",
   "holds": true,
   "id": "NET-C-agent-a-notify",
   "invariant": "agent-a/notify is VERIFIED only while its evidence is fresh"
  },
  {
   "detail": "VERIFIED",
   "holds": true,
   "id": "NET-C-agent-a-pay",
   "invariant": "agent-a/pay is VERIFIED only while its evidence is fresh"
  },
  {
   "detail": "VERIFIED",
   "holds": true,
   "id": "NET-C-agent-a-read",
   "invariant": "agent-a/read is VERIFIED only while its evidence is fresh"
  },
  {
   "detail": "VERIFIED",
   "holds": true,
   "id": "NET-C-agent-a-submit",
   "invariant": "agent-a/submit is VERIFIED only while its evidence is fresh"
  },
  {
   "detail": "VERIFIED",
   "holds": true,
   "id": "NET-C-agent-a-write",
   "invariant": "agent-a/write is VERIFIED only while its evidence is fresh"
  },
  {
   "detail": "VERIFIED",
   "holds": true,
   "id": "NET-C-agent-b-delegate",
   "invariant": "agent-b/delegate is VERIFIED only while its evidence is fresh"
  },
  {
   "detail": "VERIFIED",
   "holds": true,
   "id": "NET-C-agent-b-dispatch",
   "invariant": "agent-b/dispatch is VERIFIED only while its evidence is fresh"
  },
  {
   "detail": "VERIFIED",
   "holds": true,
   "id": "NET-C-agent-b-notify",
   "invariant": "agent-b/notify is VERIFIED only while its evidence is fresh"
  },
  {
   "detail": "VERIFIED",
   "holds": true,
   "id": "NET-C-agent-b-pay",
   "invariant": "agent-b/pay is VERIFIED only while its evidence is fresh"
  },
  {
   "detail": "VERIFIED",
   "holds": true,
   "id": "NET-C-agent-b-read",
   "invariant": "agent-b/read is VERIFIED only while its evidence is fresh"
  },
  {
   "detail": "VERIFIED",
   "holds": true,
   "id": "NET-C-agent-b-write",
   "invariant": "agent-b/write is VERIFIED only while its evidence is fresh"
  },
  {
   "detail": "VERIFIED",
   "holds": true,
   "id": "NET-C-agent-c-dispatch",
   "invariant": "agent-c/dispatch is VERIFIED only while its evidence is fresh"
  },
  {
   "detail": "VERIFIED",
   "holds": true,
   "id": "NET-C-agent-c-notify",
   "invariant": "agent-c/notify is VERIFIED only while its evidence is fresh"
  },
  {
   "detail": "VERIFIED",
   "holds": true,
   "id": "NET-C-agent-c-query",
   "invariant": "agent-c/query is VERIFIED only while its evidence is fresh"
  },
  {
   "detail": "VERIFIED",
   "holds": true,
   "id": "NET-C-agent-c-read",
   "invariant": "agent-c/read is VERIFIED only while its evidence is fresh"
  },
  {
   "detail": "VERIFIED",
   "holds": true,
   "id": "NET-C-agent-c-write",
   "invariant": "agent-c/write is VERIFIED only while its evidence is fresh"
  },
  {
   "detail": [
    "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY",
    "TRUST:TRUST_UNKNOWN:identity_trust"
   ],
   "holds": true,
   "id": "NET-T-low-identity_trust",
   "invariant": "identity_trust UNKNOWN fails a low-consequence action"
  },
  {
   "detail": [
    "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY",
    "TRUST:TRUST_UNKNOWN:identity_trust"
   ],
   "holds": true,
   "id": "NET-T-medium-identity_trust",
   "invariant": "identity_trust UNKNOWN fails a medium-consequence action"
  },
  {
   "detail": [
    "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY",
    "TRUST:TRUST_UNKNOWN:behavioral_trust"
   ],
   "holds": true,
   "id": "NET-T-medium-behavioral_trust",
   "invariant": "behavioral_trust UNKNOWN fails a medium-consequence action"
  },
  {
   "detail": [
    "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY",
    "TRUST:TRUST_UNKNOWN:security_trust"
   ],
   "holds": true,
   "id": "NET-T-medium-security_trust",
   "invariant": "security_trust UNKNOWN fails a medium-consequence action"
  },
  {
   "detail": [
    "COMPUTER_USE_WITHOUT_GOVERNED_SESSION",
    "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY",
    "TRUST:TRUST_UNKNOWN:identity_trust"
   ],
   "holds": true,
   "id": "NET-T-high-identity_trust",
   "invariant": "identity_trust UNKNOWN fails a high-consequence action"
  },
  {
   "detail": [
    "COMPUTER_USE_WITHOUT_GOVERNED_SESSION",
    "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY",
    "TRUST:TRUST_UNKNOWN:behavioral_trust"
   ],
   "holds": true,
   "id": "NET-T-high-behavioral_trust",
   "invariant": "behavioral_trust UNKNOWN fails a high-consequence action"
  },
  {
   "detail": [
    "COMPUTER_USE_WITHOUT_GOVERNED_SESSION",
    "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY",
    "TRUST:TRUST_UNKNOWN:security_trust"
   ],
   "holds": true,
   "id": "NET-T-high-security_trust",
   "invariant": "security_trust UNKNOWN fails a high-consequence action"
  },
  {
   "detail": [
    "COMPUTER_USE_WITHOUT_GOVERNED_SESSION",
    "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY",
    "TRUST:TRUST_UNKNOWN:provenance_trust"
   ],
   "holds": true,
   "id": "NET-T-high-provenance_trust",
   "invariant": "provenance_trust UNKNOWN fails a high-consequence action"
  },
  {
   "detail": [
    "COMPUTER_USE_WITHOUT_GOVERNED_SESSION",
    "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY",
    "TRUST:TRUST_UNKNOWN:execution_trust"
   ],
   "holds": true,
   "id": "NET-T-high-execution_trust",
   "invariant": "execution_trust UNKNOWN fails a high-consequence action"
  },
  {
   "detail": [
    "ARTIFACT_TAMPERED"
   ],
   "holds": true,
   "id": "NET-S-model-tamper",
   "invariant": "a tampered model is refused"
  },
  {
   "detail": [
    "ARTIFACT_VERSION_ROLLBACK"
   ],
   "holds": true,
   "id": "NET-S-model-rollback",
   "invariant": "a rolled-back model is refused"
  },
  {
   "detail": [
    "ARTIFACT_TAMPERED"
   ],
   "holds": true,
   "id": "NET-S-plugin-tamper",
   "invariant": "a tampered plugin is refused"
  },
  {
   "detail": [
    "ARTIFACT_VERSION_ROLLBACK"
   ],
   "holds": true,
   "id": "NET-S-plugin-rollback",
   "invariant": "a rolled-back plugin is refused"
  },
  {
   "detail": [
    "ARTIFACT_TAMPERED"
   ],
   "holds": true,
   "id": "NET-S-skill-tamper",
   "invariant": "a tampered skill is refused"
  },
  {
   "detail": [
    "ARTIFACT_VERSION_ROLLBACK"
   ],
   "holds": true,
   "id": "NET-S-skill-rollback",
   "invariant": "a rolled-back skill is refused"
  },
  {
   "detail": [
    "ARTIFACT_TAMPERED"
   ],
   "holds": true,
   "id": "NET-S-tool-tamper",
   "invariant": "a tampered tool is refused"
  },
  {
   "detail": [
    "ARTIFACT_VERSION_ROLLBACK"
   ],
   "holds": true,
   "id": "NET-S-tool-rollback",
   "invariant": "a rolled-back tool is refused"
  },
  {
   "detail": [
    "ARTIFACT_TAMPERED"
   ],
   "holds": true,
   "id": "NET-S-prompt-tamper",
   "invariant": "a tampered prompt is refused"
  },
  {
   "detail": [
    "ARTIFACT_VERSION_ROLLBACK"
   ],
   "holds": true,
   "id": "NET-S-prompt-rollback",
   "invariant": "a rolled-back prompt is refused"
  },
  {
   "detail": [
    "ARTIFACT_TAMPERED"
   ],
   "holds": true,
   "id": "NET-S-policy-tamper",
   "invariant": "a tampered policy is refused"
  },
  {
   "detail": [
    "ARTIFACT_VERSION_ROLLBACK"
   ],
   "holds": true,
   "id": "NET-S-policy-rollback",
   "invariant": "a rolled-back policy is refused"
  },
  {
   "detail": [
    "ARTIFACT_TAMPERED"
   ],
   "holds": true,
   "id": "NET-S-dataset-tamper",
   "invariant": "a tampered dataset is refused"
  },
  {
   "detail": [
    "ARTIFACT_VERSION_ROLLBACK"
   ],
   "holds": true,
   "id": "NET-S-dataset-rollback",
   "invariant": "a rolled-back dataset is refused"
  },
  {
   "detail": [
    "ARTIFACT_TAMPERED"
   ],
   "holds": true,
   "id": "NET-S-memory_pack-tamper",
   "invariant": "a tampered memory_pack is refused"
  },
  {
   "detail": [
    "ARTIFACT_VERSION_ROLLBACK"
   ],
   "holds": true,
   "id": "NET-S-memory_pack-rollback",
   "invariant": "a rolled-back memory_pack is refused"
  },
  {
   "detail": [
    "ARTIFACT_TAMPERED"
   ],
   "holds": true,
   "id": "NET-S-code-tamper",
   "invariant": "a tampered code is refused"
  },
  {
   "detail": [
    "ARTIFACT_VERSION_ROLLBACK"
   ],
   "holds": true,
   "id": "NET-S-code-rollback",
   "invariant": "a rolled-back code is refused"
  },
  {
   "detail": [
    "ARTIFACT_TAMPERED"
   ],
   "holds": true,
   "id": "NET-S-agent-tamper",
   "invariant": "a tampered agent is refused"
  },
  {
   "detail": [
    "ARTIFACT_VERSION_ROLLBACK"
   ],
   "holds": true,
   "id": "NET-S-agent-rollback",
   "invariant": "a rolled-back agent is refused"
  },
  {
   "detail": [
    "ARTIFACT_TAMPERED"
   ],
   "holds": true,
   "id": "NET-S-container-tamper",
   "invariant": "a tampered container is refused"
  },
  {
   "detail": [
    "ARTIFACT_VERSION_ROLLBACK"
   ],
   "holds": true,
   "id": "NET-S-container-rollback",
   "invariant": "a rolled-back container is refused"
  },
  {
   "detail": [
    "CALLER_IDENTITY_PROVIDER_UNAVAILABLE",
    "DEPENDENCY_UNAVAILABLE:identity-provider",
    "TARGET_IDENTITY_PROVIDER_UNAVAILABLE"
   ],
   "holds": true,
   "id": "NET-O-identity-provider",
   "invariant": "identity-provider outage denies instead of trusting"
  },
  {
   "detail": [
    "CAPABILITY_UNKNOWN",
    "CROSS_DOMAIN_AUTHORITY_UNKNOWN",
    "DEPENDENCY_UNAVAILABLE:attestation-provider"
   ],
   "holds": true,
   "id": "NET-O-attestation-provider",
   "invariant": "attestation-provider outage denies instead of trusting"
  },
  {
   "detail": [
    "CROSS_DOMAIN_AUTHORITY_UNKNOWN",
    "DEPENDENCY_UNAVAILABLE:trust-provider",
    "TRUST:TRUST_UNKNOWN:behavioral_trust",
    "TRUST:TRUST_UNKNOWN:identity_trust",
    "TRUST:TRUST_UNKNOWN:security_trust"
   ],
   "holds": true,
   "id": "NET-O-trust-provider",
   "invariant": "trust-provider outage denies instead of trusting"
  },
  {
   "detail": [
    "DEPENDENCY_UNAVAILABLE:revocation-provider"
   ],
   "holds": true,
   "id": "NET-O-revocation-provider",
   "invariant": "revocation-provider outage denies instead of trusting"
  },
  {
   "detail": [
    "DEPENDENCY_UNAVAILABLE:evidence-provider"
   ],
   "holds": true,
   "id": "NET-O-evidence-provider",
   "invariant": "evidence-provider outage denies instead of trusting"
  },
  {
   "detail": [
    {
     "expected": true,
     "got": true
    },
    {
     "expected": true,
     "got": true
    }
   ],
   "holds": true,
   "id": "NET-E-communicated",
   "invariant": "incident exposure via 'communicated' follows the influence direction"
  },
  {
   "detail": [
    {
     "expected": false,
     "got": false
    },
    {
     "expected": true,
     "got": true
    }
   ],
   "holds": true,
   "id": "NET-E-delegated_to",
   "invariant": "incident exposure via 'delegated_to' follows the influence direction"
  },
  {
   "detail": [
    {
     "expected": false,
     "got": false
    },
    {
     "expected": true,
     "got": true
    }
   ],
   "holds": true,
   "id": "NET-E-trusted",
   "invariant": "incident exposure via 'trusted' follows the influence direction"
  },
  {
   "detail": [
    {
     "expected": true,
     "got": true
    },
    {
     "expected": false,
     "got": false
    }
   ],
   "holds": true,
   "id": "NET-E-received_artifact",
   "invariant": "incident exposure via 'received_artifact' follows the influence direction"
  },
  {
   "detail": [
    {
     "expected": true,
     "got": true
    },
    {
     "expected": false,
     "got": false
    }
   ],
   "holds": true,
   "id": "NET-E-imported_output",
   "invariant": "incident exposure via 'imported_output' follows the influence direction"
  },
  {
   "detail": [
    {
     "expected": true,
     "got": true
    },
    {
     "expected": false,
     "got": false
    }
   ],
   "holds": true,
   "id": "NET-E-executed_recommendation",
   "invariant": "incident exposure via 'executed_recommendation' follows the influence direction"
  },
  {
   "detail": [
    {
     "expected": true,
     "got": true
    },
    {
     "expected": true,
     "got": true
    }
   ],
   "holds": true,
   "id": "NET-E-exchanged_credentials",
   "invariant": "incident exposure via 'exchanged_credentials' follows the influence direction"
  },
  {
   "detail": [
    {
     "expected": true,
     "got": true
    },
    {
     "expected": true,
     "got": true
    }
   ],
   "holds": true,
   "id": "NET-E-contracted",
   "invariant": "incident exposure via 'contracted' follows the influence direction"
  },
  {
   "detail": {
    "dispatch": "VERIFIED",
    "teleport": "CLAIMED"
   },
   "holds": true,
   "id": "NET-L01",
   "invariant": "NET-L01 DISCOVERY IS NOT TRUST"
  },
  {
   "detail": {
    "authority": "NONE",
    "effective": [
     "read"
    ],
    "ignored_inputs": [
     "trust_score"
    ],
    "state": "COMPILED",
    "unknown_factors": []
   },
   "holds": true,
   "id": "NET-L02",
   "invariant": "NET-L02 TRUST IS NOT AUTHORITY"
  },
  {
   "detail": "425fb4d1cea7e22aa5fbd20b8eb7e7c4c9bb32a6deae24748b81f53511ac539e",
   "holds": true,
   "id": "NET-L03",
   "invariant": "NET-L03 AUTHORITY IS NOT AUTHORIZATION"
  },
  {
   "detail": [
    "AUTHORIZED",
    "DENY"
   ],
   "holds": true,
   "id": "NET-L04",
   "invariant": "NET-L04 AUTHORIZATION IS NOT EXECUTION"
  },
  {
   "detail": [],
   "holds": true,
   "id": "NET-L05",
   "invariant": "NET-L05 EXECUTION IS NOT SUCCESS"
  },
  {
   "detail": [
    "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
   ],
   "holds": true,
   "id": "NET-L06",
   "invariant": "NET-L06 SUCCESS IS NOT TRUST"
  },
  {
   "detail": [
    "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
   ],
   "holds": true,
   "id": "NET-L07",
   "invariant": "NET-L07 NEGOTIATION IS NOT AUTHORIZATION"
  },
  {
   "detail": [
    "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
   ],
   "holds": true,
   "id": "NET-L08",
   "invariant": "NET-L08 CONTRACT IS NOT AUTHORITY"
  },
  {
   "detail": [
    "COMPUTER_USE_WITHOUT_GOVERNED_SESSION",
    "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
   ],
   "holds": true,
   "id": "NET-L09",
   "invariant": "NET-L09 MONEY IS NOT AUTHORITY"
  },
  {
   "detail": 0.5,
   "holds": true,
   "id": "NET-L10",
   "invariant": "NET-L10 REPUTATION IS NOT AUTHORITY"
  },
  {
   "detail": [
    "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
   ],
   "holds": true,
   "id": "NET-L11",
   "invariant": "NET-L11 FEDERATION IS NOT UNLIMITED TRUST"
  },
  {
   "detail": [
    "CALLER_IDENTITY_SIGNATURE_INVALID",
    "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
   ],
   "holds": true,
   "id": "NET-L12",
   "invariant": "NET-L12 IDENTITY DOES NOT IMPLY AUTHORITY"
  },
  {
   "detail": {
    "dispatch": "VERIFIED",
    "teleport": "CLAIMED"
   },
   "holds": true,
   "id": "NET-L13",
   "invariant": "NET-L13 A CAPABILITY ADVERTISEMENT IS A CLAIM"
  },
  {
   "detail": [
    "DEPENDENCY_UNAVAILABLE:network-partition:dom-b"
   ],
   "holds": true,
   "id": "NET-L14",
   "invariant": "NET-L14 LOSS OF CONNECTIVITY NEVER CREATES AUTHORITY"
  },
  {
   "detail": "UNKNOWN",
   "holds": true,
   "id": "NET-L15",
   "invariant": "NET-L15 UNKNOWN NEVER BECOMES TRUSTED"
  },
  {
   "detail": [
    "AGENT_STATE_QUARANTINED:agent-a",
    "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
   ],
   "holds": true,
   "id": "NET-L16",
   "invariant": "NET-L16 QUARANTINE ONLY REDUCES AUTHORITY"
  },
  {
   "detail": [
    "RECOVERY_CANARY_NOT_PASSED"
   ],
   "holds": true,
   "id": "NET-L17",
   "invariant": "NET-L17 RECOVERY IS NOT TRUST RESTORATION"
  },
  {
   "detail": [
    "DENY",
    [
     "CAPABILITY_CLAIMED",
     "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
    ]
   ],
   "holds": true,
   "id": "NET-L18",
   "invariant": "NET-L18 NO PROTOCOL BYPASSES E8"
  },
  {
   "detail": [
    "MEMORY_CANNOT_CARRY_AUTHORITY_OR_INSTRUCTIONS"
   ],
   "holds": true,
   "id": "NET-L19",
   "invariant": "NET-L19 MEMORY IS NOT TRUST, AUTHORITY OR FACT"
  },
  {
   "detail": [
    {
     "authority_changed": false,
     "provider": "agent-c",
     "routed": true
    },
    [
     "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
    ]
   ],
   "holds": true,
   "id": "NET-L20",
   "invariant": "NET-L20 ROUTING NEVER CHANGES AUTHORITY"
  },
  {
   "detail": {
    "authorized": true,
    "derivable": true,
    "reasons": []
   },
   "holds": true,
   "id": "NET-SOUND-agent-a-agent-b-read",
   "invariant": "agent-a -> agent-b read: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": true,
    "derivable": true,
    "reasons": []
   },
   "holds": true,
   "id": "NET-SOUND-agent-a-agent-b-notify",
   "invariant": "agent-a -> agent-b notify: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": true,
    "derivable": true,
    "reasons": []
   },
   "holds": true,
   "id": "NET-SOUND-agent-a-agent-b-dispatch",
   "invariant": "agent-a -> agent-b dispatch: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": true,
    "derivable": true,
    "reasons": []
   },
   "holds": true,
   "id": "NET-SOUND-agent-a-agent-b-write",
   "invariant": "agent-a -> agent-b write: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": false,
    "derivable": false,
    "reasons": [
     "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
    ]
   },
   "holds": true,
   "id": "NET-SOUND-agent-a-agent-c-read",
   "invariant": "agent-a -> agent-c read: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": false,
    "derivable": false,
    "reasons": [
     "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
    ]
   },
   "holds": true,
   "id": "NET-SOUND-agent-a-agent-c-notify",
   "invariant": "agent-a -> agent-c notify: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": false,
    "derivable": false,
    "reasons": [
     "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
    ]
   },
   "holds": true,
   "id": "NET-SOUND-agent-a-agent-c-dispatch",
   "invariant": "agent-a -> agent-c dispatch: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": false,
    "derivable": false,
    "reasons": [
     "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
    ]
   },
   "holds": true,
   "id": "NET-SOUND-agent-a-agent-c-write",
   "invariant": "agent-a -> agent-c write: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": true,
    "derivable": true,
    "reasons": []
   },
   "holds": true,
   "id": "NET-SOUND-agent-a-agent-a2-read",
   "invariant": "agent-a -> agent-a2 read: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": true,
    "derivable": true,
    "reasons": []
   },
   "holds": true,
   "id": "NET-SOUND-agent-a-agent-a2-notify",
   "invariant": "agent-a -> agent-a2 notify: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": false,
    "derivable": false,
    "reasons": [
     "CAPABILITY_CLAIMED",
     "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
    ]
   },
   "holds": true,
   "id": "NET-SOUND-agent-a-agent-a2-dispatch",
   "invariant": "agent-a -> agent-a2 dispatch: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": true,
    "derivable": true,
    "reasons": []
   },
   "holds": true,
   "id": "NET-SOUND-agent-a-agent-a2-write",
   "invariant": "agent-a -> agent-a2 write: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": false,
    "derivable": false,
    "reasons": [
     "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
    ]
   },
   "holds": true,
   "id": "NET-SOUND-agent-a-agent-c2-read",
   "invariant": "agent-a -> agent-c2 read: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": false,
    "derivable": false,
    "reasons": [
     "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
    ]
   },
   "holds": true,
   "id": "NET-SOUND-agent-a-agent-c2-notify",
   "invariant": "agent-a -> agent-c2 notify: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": false,
    "derivable": false,
    "reasons": [
     "CAPABILITY_CLAIMED",
     "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
    ]
   },
   "holds": true,
   "id": "NET-SOUND-agent-a-agent-c2-dispatch",
   "invariant": "agent-a -> agent-c2 dispatch: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": false,
    "derivable": false,
    "reasons": [
     "CAPABILITY_CLAIMED",
     "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
    ]
   },
   "holds": true,
   "id": "NET-SOUND-agent-a-agent-c2-write",
   "invariant": "agent-a -> agent-c2 write: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": true,
    "derivable": true,
    "reasons": []
   },
   "holds": true,
   "id": "NET-SOUND-agent-b-agent-a-read",
   "invariant": "agent-b -> agent-a read: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": true,
    "derivable": true,
    "reasons": []
   },
   "holds": true,
   "id": "NET-SOUND-agent-b-agent-a-notify",
   "invariant": "agent-b -> agent-a notify: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": true,
    "derivable": true,
    "reasons": []
   },
   "holds": true,
   "id": "NET-SOUND-agent-b-agent-a-dispatch",
   "invariant": "agent-b -> agent-a dispatch: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": true,
    "derivable": true,
    "reasons": []
   },
   "holds": true,
   "id": "NET-SOUND-agent-b-agent-a-write",
   "invariant": "agent-b -> agent-a write: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": true,
    "derivable": true,
    "reasons": []
   },
   "holds": true,
   "id": "NET-SOUND-agent-b-agent-c-read",
   "invariant": "agent-b -> agent-c read: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": true,
    "derivable": true,
    "reasons": []
   },
   "holds": true,
   "id": "NET-SOUND-agent-b-agent-c-notify",
   "invariant": "agent-b -> agent-c notify: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": true,
    "derivable": true,
    "reasons": []
   },
   "holds": true,
   "id": "NET-SOUND-agent-b-agent-c-dispatch",
   "invariant": "agent-b -> agent-c dispatch: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": true,
    "derivable": true,
    "reasons": []
   },
   "holds": true,
   "id": "NET-SOUND-agent-b-agent-c-write",
   "invariant": "agent-b -> agent-c write: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": true,
    "derivable": true,
    "reasons": []
   },
   "holds": true,
   "id": "NET-SOUND-agent-b-agent-a2-read",
   "invariant": "agent-b -> agent-a2 read: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": true,
    "derivable": true,
    "reasons": []
   },
   "holds": true,
   "id": "NET-SOUND-agent-b-agent-a2-notify",
   "invariant": "agent-b -> agent-a2 notify: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": false,
    "derivable": false,
    "reasons": [
     "CAPABILITY_CLAIMED",
     "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
    ]
   },
   "holds": true,
   "id": "NET-SOUND-agent-b-agent-a2-dispatch",
   "invariant": "agent-b -> agent-a2 dispatch: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": true,
    "derivable": true,
    "reasons": []
   },
   "holds": true,
   "id": "NET-SOUND-agent-b-agent-a2-write",
   "invariant": "agent-b -> agent-a2 write: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": true,
    "derivable": true,
    "reasons": []
   },
   "holds": true,
   "id": "NET-SOUND-agent-b-agent-c2-read",
   "invariant": "agent-b -> agent-c2 read: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": true,
    "derivable": true,
    "reasons": []
   },
   "holds": true,
   "id": "NET-SOUND-agent-b-agent-c2-notify",
   "invariant": "agent-b -> agent-c2 notify: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": false,
    "derivable": false,
    "reasons": [
     "CAPABILITY_CLAIMED",
     "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
    ]
   },
   "holds": true,
   "id": "NET-SOUND-agent-b-agent-c2-dispatch",
   "invariant": "agent-b -> agent-c2 dispatch: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": false,
    "derivable": false,
    "reasons": [
     "CAPABILITY_CLAIMED",
     "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
    ]
   },
   "holds": true,
   "id": "NET-SOUND-agent-b-agent-c2-write",
   "invariant": "agent-b -> agent-c2 write: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": false,
    "derivable": false,
    "reasons": [
     "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
    ]
   },
   "holds": true,
   "id": "NET-SOUND-agent-c-agent-a-read",
   "invariant": "agent-c -> agent-a read: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": false,
    "derivable": false,
    "reasons": [
     "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
    ]
   },
   "holds": true,
   "id": "NET-SOUND-agent-c-agent-a-notify",
   "invariant": "agent-c -> agent-a notify: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": false,
    "derivable": false,
    "reasons": [
     "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
    ]
   },
   "holds": true,
   "id": "NET-SOUND-agent-c-agent-a-dispatch",
   "invariant": "agent-c -> agent-a dispatch: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": false,
    "derivable": false,
    "reasons": [
     "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
    ]
   },
   "holds": true,
   "id": "NET-SOUND-agent-c-agent-a-write",
   "invariant": "agent-c -> agent-a write: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": true,
    "derivable": true,
    "reasons": []
   },
   "holds": true,
   "id": "NET-SOUND-agent-c-agent-b-read",
   "invariant": "agent-c -> agent-b read: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": true,
    "derivable": true,
    "reasons": []
   },
   "holds": true,
   "id": "NET-SOUND-agent-c-agent-b-notify",
   "invariant": "agent-c -> agent-b notify: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": true,
    "derivable": true,
    "reasons": []
   },
   "holds": true,
   "id": "NET-SOUND-agent-c-agent-b-dispatch",
   "invariant": "agent-c -> agent-b dispatch: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": true,
    "derivable": true,
    "reasons": []
   },
   "holds": true,
   "id": "NET-SOUND-agent-c-agent-b-write",
   "invariant": "agent-c -> agent-b write: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": false,
    "derivable": false,
    "reasons": [
     "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
    ]
   },
   "holds": true,
   "id": "NET-SOUND-agent-c-agent-a2-read",
   "invariant": "agent-c -> agent-a2 read: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": false,
    "derivable": false,
    "reasons": [
     "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
    ]
   },
   "holds": true,
   "id": "NET-SOUND-agent-c-agent-a2-notify",
   "invariant": "agent-c -> agent-a2 notify: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": false,
    "derivable": false,
    "reasons": [
     "CAPABILITY_CLAIMED",
     "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
    ]
   },
   "holds": true,
   "id": "NET-SOUND-agent-c-agent-a2-dispatch",
   "invariant": "agent-c -> agent-a2 dispatch: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": false,
    "derivable": false,
    "reasons": [
     "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
    ]
   },
   "holds": true,
   "id": "NET-SOUND-agent-c-agent-a2-write",
   "invariant": "agent-c -> agent-a2 write: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": true,
    "derivable": true,
    "reasons": []
   },
   "holds": true,
   "id": "NET-SOUND-agent-c-agent-c2-read",
   "invariant": "agent-c -> agent-c2 read: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": true,
    "derivable": true,
    "reasons": []
   },
   "holds": true,
   "id": "NET-SOUND-agent-c-agent-c2-notify",
   "invariant": "agent-c -> agent-c2 notify: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": false,
    "derivable": false,
    "reasons": [
     "CAPABILITY_CLAIMED",
     "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
    ]
   },
   "holds": true,
   "id": "NET-SOUND-agent-c-agent-c2-dispatch",
   "invariant": "agent-c -> agent-c2 dispatch: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": false,
    "derivable": false,
    "reasons": [
     "CAPABILITY_CLAIMED",
     "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
    ]
   },
   "holds": true,
   "id": "NET-SOUND-agent-c-agent-c2-write",
   "invariant": "agent-c -> agent-c2 write: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": true,
    "derivable": true,
    "reasons": []
   },
   "holds": true,
   "id": "NET-SOUND-agent-a2-agent-a-read",
   "invariant": "agent-a2 -> agent-a read: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": true,
    "derivable": true,
    "reasons": []
   },
   "holds": true,
   "id": "NET-SOUND-agent-a2-agent-a-notify",
   "invariant": "agent-a2 -> agent-a notify: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": false,
    "derivable": false,
    "reasons": [
     "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
    ]
   },
   "holds": true,
   "id": "NET-SOUND-agent-a2-agent-a-dispatch",
   "invariant": "agent-a2 -> agent-a dispatch: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": true,
    "derivable": true,
    "reasons": []
   },
   "holds": true,
   "id": "NET-SOUND-agent-a2-agent-a-write",
   "invariant": "agent-a2 -> agent-a write: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": true,
    "derivable": true,
    "reasons": []
   },
   "holds": true,
   "id": "NET-SOUND-agent-a2-agent-b-read",
   "invariant": "agent-a2 -> agent-b read: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": true,
    "derivable": true,
    "reasons": []
   },
   "holds": true,
   "id": "NET-SOUND-agent-a2-agent-b-notify",
   "invariant": "agent-a2 -> agent-b notify: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": false,
    "derivable": false,
    "reasons": [
     "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
    ]
   },
   "holds": true,
   "id": "NET-SOUND-agent-a2-agent-b-dispatch",
   "invariant": "agent-a2 -> agent-b dispatch: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": true,
    "derivable": true,
    "reasons": []
   },
   "holds": true,
   "id": "NET-SOUND-agent-a2-agent-b-write",
   "invariant": "agent-a2 -> agent-b write: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": false,
    "derivable": false,
    "reasons": [
     "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
    ]
   },
   "holds": true,
   "id": "NET-SOUND-agent-a2-agent-c-read",
   "invariant": "agent-a2 -> agent-c read: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": false,
    "derivable": false,
    "reasons": [
     "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
    ]
   },
   "holds": true,
   "id": "NET-SOUND-agent-a2-agent-c-notify",
   "invariant": "agent-a2 -> agent-c notify: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": false,
    "derivable": false,
    "reasons": [
     "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
    ]
   },
   "holds": true,
   "id": "NET-SOUND-agent-a2-agent-c-dispatch",
   "invariant": "agent-a2 -> agent-c dispatch: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": false,
    "derivable": false,
    "reasons": [
     "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
    ]
   },
   "holds": true,
   "id": "NET-SOUND-agent-a2-agent-c-write",
   "invariant": "agent-a2 -> agent-c write: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": false,
    "derivable": false,
    "reasons": [
     "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
    ]
   },
   "holds": true,
   "id": "NET-SOUND-agent-a2-agent-c2-read",
   "invariant": "agent-a2 -> agent-c2 read: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": false,
    "derivable": false,
    "reasons": [
     "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
    ]
   },
   "holds": true,
   "id": "NET-SOUND-agent-a2-agent-c2-notify",
   "invariant": "agent-a2 -> agent-c2 notify: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": false,
    "derivable": false,
    "reasons": [
     "CAPABILITY_CLAIMED",
     "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
    ]
   },
   "holds": true,
   "id": "NET-SOUND-agent-a2-agent-c2-dispatch",
   "invariant": "agent-a2 -> agent-c2 dispatch: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": false,
    "derivable": false,
    "reasons": [
     "CAPABILITY_CLAIMED",
     "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
    ]
   },
   "holds": true,
   "id": "NET-SOUND-agent-a2-agent-c2-write",
   "invariant": "agent-a2 -> agent-c2 write: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": false,
    "derivable": false,
    "reasons": [
     "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
    ]
   },
   "holds": true,
   "id": "NET-SOUND-agent-c2-agent-a-read",
   "invariant": "agent-c2 -> agent-a read: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": false,
    "derivable": false,
    "reasons": [
     "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
    ]
   },
   "holds": true,
   "id": "NET-SOUND-agent-c2-agent-a-notify",
   "invariant": "agent-c2 -> agent-a notify: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": false,
    "derivable": false,
    "reasons": [
     "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
    ]
   },
   "holds": true,
   "id": "NET-SOUND-agent-c2-agent-a-dispatch",
   "invariant": "agent-c2 -> agent-a dispatch: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": false,
    "derivable": false,
    "reasons": [
     "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
    ]
   },
   "holds": true,
   "id": "NET-SOUND-agent-c2-agent-a-write",
   "invariant": "agent-c2 -> agent-a write: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": true,
    "derivable": true,
    "reasons": []
   },
   "holds": true,
   "id": "NET-SOUND-agent-c2-agent-b-read",
   "invariant": "agent-c2 -> agent-b read: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": true,
    "derivable": true,
    "reasons": []
   },
   "holds": true,
   "id": "NET-SOUND-agent-c2-agent-b-notify",
   "invariant": "agent-c2 -> agent-b notify: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": false,
    "derivable": false,
    "reasons": [
     "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
    ]
   },
   "holds": true,
   "id": "NET-SOUND-agent-c2-agent-b-dispatch",
   "invariant": "agent-c2 -> agent-b dispatch: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": false,
    "derivable": false,
    "reasons": [
     "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
    ]
   },
   "holds": true,
   "id": "NET-SOUND-agent-c2-agent-b-write",
   "invariant": "agent-c2 -> agent-b write: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": true,
    "derivable": true,
    "reasons": []
   },
   "holds": true,
   "id": "NET-SOUND-agent-c2-agent-c-read",
   "invariant": "agent-c2 -> agent-c read: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": true,
    "derivable": true,
    "reasons": []
   },
   "holds": true,
   "id": "NET-SOUND-agent-c2-agent-c-notify",
   "invariant": "agent-c2 -> agent-c notify: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": false,
    "derivable": false,
    "reasons": [
     "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
    ]
   },
   "holds": true,
   "id": "NET-SOUND-agent-c2-agent-c-dispatch",
   "invariant": "agent-c2 -> agent-c dispatch: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": false,
    "derivable": false,
    "reasons": [
     "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
    ]
   },
   "holds": true,
   "id": "NET-SOUND-agent-c2-agent-c-write",
   "invariant": "agent-c2 -> agent-c write: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": false,
    "derivable": false,
    "reasons": [
     "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
    ]
   },
   "holds": true,
   "id": "NET-SOUND-agent-c2-agent-a2-read",
   "invariant": "agent-c2 -> agent-a2 read: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": false,
    "derivable": false,
    "reasons": [
     "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
    ]
   },
   "holds": true,
   "id": "NET-SOUND-agent-c2-agent-a2-notify",
   "invariant": "agent-c2 -> agent-a2 notify: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": false,
    "derivable": false,
    "reasons": [
     "CAPABILITY_CLAIMED",
     "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
    ]
   },
   "holds": true,
   "id": "NET-SOUND-agent-c2-agent-a2-dispatch",
   "invariant": "agent-c2 -> agent-a2 dispatch: authorized only if independently derivable, via E8"
  },
  {
   "detail": {
    "authorized": false,
    "derivable": false,
    "reasons": [
     "NO_CROSS_DOMAIN_AUTHORITY_FOR_CAPABILITY"
    ]
   },
   "holds": true,
   "id": "NET-SOUND-agent-c2-agent-a2-write",
   "invariant": "agent-c2 -> agent-a2 write: authorized only if independently derivable, via E8"
  },
  {
   "detail": "a2a",
   "holds": true,
   "id": "NET-U-a2a",
   "invariant": "a2a: an unmapped operation normalizes to UNKNOWN (never to a capability)"
  },
  {
   "detail": "mcp",
   "holds": true,
   "id": "NET-U-mcp",
   "invariant": "mcp: an unmapped operation normalizes to UNKNOWN (never to a capability)"
  },
  {
   "detail": "http",
   "holds": true,
   "id": "NET-U-http",
   "invariant": "http: an unmapped operation normalizes to UNKNOWN (never to a capability)"
  },
  {
   "detail": "rest",
   "holds": true,
   "id": "NET-U-rest",
   "invariant": "rest: an unmapped operation normalizes to UNKNOWN (never to a capability)"
  },
  {
   "detail": "grpc",
   "holds": true,
   "id": "NET-U-grpc",
   "invariant": "grpc: an unmapped operation normalizes to UNKNOWN (never to a capability)"
  },
  {
   "detail": "websocket",
   "holds": true,
   "id": "NET-U-websocket",
   "invariant": "websocket: an unmapped operation normalizes to UNKNOWN (never to a capability)"
  },
  {
   "detail": "event_bus",
   "holds": true,
   "id": "NET-U-event_bus",
   "invariant": "event_bus: an unmapped operation normalizes to UNKNOWN (never to a capability)"
  },
  {
   "detail": "message_queue",
   "holds": true,
   "id": "NET-U-message_queue",
   "invariant": "message_queue: an unmapped operation normalizes to UNKNOWN (never to a capability)"
  },
  {
   "detail": "cli",
   "holds": true,
   "id": "NET-U-cli",
   "invariant": "cli: an unmapped operation normalizes to UNKNOWN (never to a capability)"
  },
  {
   "detail": "browser",
   "holds": true,
   "id": "NET-U-browser",
   "invariant": "browser: an unmapped operation normalizes to UNKNOWN (never to a capability)"
  },
  {
   "detail": "computer_use",
   "holds": true,
   "id": "NET-U-computer_use",
   "invariant": "computer_use: an unmapped operation normalizes to UNKNOWN (never to a capability)"
  },
  {
   "detail": "local_ipc",
   "holds": true,
   "id": "NET-U-local_ipc",
   "invariant": "local_ipc: an unmapped operation normalizes to UNKNOWN (never to a capability)"
  },
  {
   "detail": "cloud_api",
   "holds": true,
   "id": "NET-U-cloud_api",
   "invariant": "cloud_api: an unmapped operation normalizes to UNKNOWN (never to a capability)"
  },
  {
   "detail": [],
   "holds": true,
   "id": "NET-S-bench-targets",
   "invariant": "every adversarial scenario names an invariant that exists"
  }
 ],
 "duplicate_ids": [],
 "failed": [],
 "holding": 305,
 "schema": "cain42.e24.invariants.v1"
}
